{
  "$comment": "Signing roots of Nolle Engineering GmbH. A QES instrument signs its own record with a key generated inside its secure element; this document publishes the root that certifies which instruments are ours, so the chain can be checked without trusting any single channel.",
  "issuer": "Nolle Engineering GmbH",
  "updated": "2026-09-20",
  "roots": [
    {
      "key_id": "ROOT-NE-01",
      "curve": "P-256",
      "status": "active",
      "created": "2026-09-20",
      "pubkey": "047af26dbabb67c7d99d4802768111ccf14c994995c0cd7a88d263651225167d9ab10d73e79c02bc1d148d3fa2bd498373725e053d2ab79260ab8b25db268379c3",
      "fingerprint": "098e001dd525097e",
      "purpose": "certifies the public keys of QES instruments; signs nothing else, and never signs measurement data"
    }
  ],
  "nodes": [
    {
      "node_id": "QES-BENCH-01",
      "secure_element": "ATECC608B",
      "serial": "0123fa5fbc907163ee",
      "pubkey": "04b92ed54e8663d2863b421015223858dc517c6ca6ce232093020c0bf5656823dbd48304e285a6f954fd3e6b06fcfa778dc19034723aa85bef6c9fa03d3fba30b5",
      "fingerprint": "083ad19f9de95d8b",
      "certified_by": "ROOT-NE-01",
      "certified": "2026-09-20",
      "certificate": "https://gitlab.nolle.engineering/qes/records/-/raw/main/certs/QES-BENCH-01_0123fa5fbc907163ee_2026-09-20.json"
    }
  ],
  "tool": "https://gitlab.nolle.engineering/qes/tools",
  "records": "https://gitlab.nolle.engineering/qes/records",
  "format": "https://nolle.engineering/qes/record-format",
  "howto": "python3 qes.py verify <record.pkt> --cert <node cert> --issuer-pubkey 04<root pubkey>",
  "revocation": "No key listed here has been revoked. A revoked key would remain listed with status 'revoked' and a date; it is never silently removed."
}